From 3d3f8c4721fd0c978243d365d7ac8eaea1124b17 Mon Sep 17 00:00:00 2001 From: Gregor Kleen Date: Mon, 14 Mar 2022 17:00:42 +0100 Subject: installer: allow input --- installer/ruleset.nft | 3 +++ 1 file changed, 3 insertions(+) (limited to 'installer') diff --git a/installer/ruleset.nft b/installer/ruleset.nft index 4de54dd7..803ce9fd 100644 --- a/installer/ruleset.nft +++ b/installer/ruleset.nft @@ -73,6 +73,9 @@ table inet filter { udp dport 60000-61000 counter accept + ct state {established, related} counter name established-rx accept + + limit name lim_reject log level debug prefix "drop input: " counter drop log level debug prefix "reject input: " counter meta l4proto tcp ct state new counter reject with tcp reset -- cgit v1.2.3